Sign in

hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪

@hrbrmstr.mastodon.social.ap.brid.gy
508 followers 17 following 6K posts

Pampa • Don't look @ me…I do what he does—just slower. #rstats avuncular • 👨‍🍳 • ✝️ • 💤 • VP Super Intelligence/ML @ Censys • Carnegie Mellon lecturer […] 🌉 bridged from ⁂ mastodon.social/@hrbrmstr, follow @ap.brid.gy to interact

PostsRepliesMedia
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 1h
this is why i plotted the refinery map thing earlier. looks like my estimates were low (but they were based on the guidelines they use, so they're either being hyper cautios b/c the storms can do real damage and these facilities are at 95% continuous capacity which makes them more brittle anyway […]
mastodon.social
Original post on mastodon.social
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 3h
fwiw empty datacenters are being built all across the country in places w/o many eyes at all.
hachyderm.io
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 4h
#protip if you're gonna bother to take up resume space with a link to your GitHub (or other social coding site) URL, perhaps not have it be a handful dead projects and a slightly bigger handful of *very* old and untouched forks of other repos.
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 6h
The $500 Dyson CameraJet (AI water jet toothbrush with an integrated camera) is, apparently, an abject failure, with liquids leaking into the interior and shorting out the circuits. Daftest. Timeline. Ever.
000
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Sophie Labelle @assignedmale.bsky.social · 17h
It's never too late.
3435142
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 8h
Plotted refineries (sided by capacity) onto the latest Cyclocane spaghetti model of the new Gulf of Mexico hurricane and it looks like most refineries are out of the direct path. Between ~3% and ~10% of refineries may need to pause production, but shutdown […] [Original post on mastodon.social]
Map of the Gulf of Mexico showing a hurricane forecast ensemble that curves from the western Gulf toward southeast Louisiana and Mississippi, overlaid with U.S. petroleum refineries sized by capacity. The heaviest refining clusters sit along the Texas and Louisiana coasts, with the Baton Rouge to New Orleans corridor directly under the forecast tracks.
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 8h
Yesterday's [c]git wars battle was successful, and it turns out the new Akin fingerprint technique developed by @HoneyLabs has bonkers merit. The majority of blocks are from two distributed residential proxy fleets, and gosh, they were persistent buggers […] [Original post on mastodon.social]
The image is a stacked bar chart titled Status of the /git/* wars. The vertical axis represents the number of requests, ranging from 0 to 60,000. The horizontal axis shows a timeline from September 21st to early October, with markers for Sep 21, Sep 28, and Oct 05.

There are three categories of requests represented by different colors. Blue represents requests that Slipped Through Bot or were from Legit Humans. Yellow represents Server Forced Aborts. A dark red color represents the Akin Trigger.

From September 21st to early October, most requests consist of a blue base with varying amounts of yellow on top. The total number of requests generally stays below 40,000 during this period, though there is a peak around October 2nd.

Toward the end of the timeline, after October 5th, there is a dramatic change. While blue and yellow requests continue, a huge spike of dark red Akin Trigger requests appears. In one particular bar, the dark red category towers over the others, pushing the total request count well above 60,000, the highest point on the chart. The final bar shows a smaller total volume, but it is still composed mostly of the dark red Akin Trigger requests.This image is a table displaying data about various tokens and their associated network activity. The table consists of five columns: Token, Reqs (requests), IPs, User agent, and Geography.

The first row shows a token beginning with b11cun110 and ending in a97cf4, which has over 19,000 requests from 2,824 IP addresses. Its user agents are listed as rotating Linux Firefox, desktop Chrome, and Windows, and its geography includes Brazil, Argentina, Russia, Bangladesh, and Morocco.

The second row lists a token beginning with b11cun110 and ending in 9272d6, with over 12,000 requests from 1,897 IP addresses. It uses iPhone FxiOS with 290 rotated UA strings and originates from Brazil, Argentina, the United States, Bangladesh, and Chile.

The third row features a token beginning with b11cun140 and ending in fa6db4, which has over 10,000 requests from 1,415 IP addresses. It uses Android Chrome with 587 rotated device UAs and originates from Brazil, Argentina, Russia, the United States, and Morocco.

The fourth row shows a token beginning with b20hun120 and ending in 528a29, which has 3,541 requests from 3,512 IP addresses. It uses Desktop Chrome or macOS and originates from the United States, South Carolina, Great Britain, Lithuania, and Latvia.

The fifth row lists a token beginning with b11cun110 and ending in f24e77, with 3,418 requests from 492 IP addresses. It uses rotated mobile UAs and originates from Brazil, Argentina, Russia, Morocco, and the United States.

The sixth row shows a token beginning with b20hun100 and ending in 8e704f, with 2,340 requests from 83 IP addresses. Its user agent begins with meta-externalagent/1 and its geography is Ireland (AS32934).

The final row shows a token beginning with b20hun040 and ending in fb5231, which has 731 requests from 61 IP addresses. Like the previous row, it uses a user agent starting with meta-externalagent/1 and originates from Ireland (AS32934).
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 21h
Go on, please tell me abt how rock solid HTTPS is.
infosec.exchange
100
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Todd @toddgrotenhuis.bsky.social · 21h
Do I know anybody working with Zig? ziglang.org I am zigcurious.
ziglang.org
Home ⚡ Zig Programming Language
002
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 23h
Early voted!
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
seriously impressive self-hostable text-to-speech model that works super fast **on CPU** — cactuscompute.com/blog/whistle their fine-tunable + self-hostable Needle automation model is also impressive — cactuscompute.com/needle
cactuscompute.com
Whistle: Speech to Text in 16.9 MB
An open speech recognition model that runs on the same CPU engine as Needle. It transcribes seven languages, reaches the first token in 11 ms, and loads beside Needle so one binary turns a clip straight into tool calls.
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
Chrome (Desktop—stable) CVE report is up — tbljrmp60k.joplinusercontent.com/sh… Notable: - 34 Use After Free, 12 race, 4 type confusion, 4 OOB, 3 integer overflow; 190 uncategorized. - XR largest component bucket (51) […] [Original post on mastodon.social]
This release contains **247 CVEs** across **4 severity levels** with a total bounty pool of **$33,000**.

- **Critical:** 4
- **High:** 53
- **Medium:** 122
- **Low:** 68
- **Bounty-bearing:** 16
- **External reporters:** 40

## Vulnerability Type Breakdown

| Type | Count | % of Total |
|------|-------|-----------|
| Other | 190 | 76.9% |
| Use After Free | 34 | 13.8% |
| Race Condition | 12 | 4.9% |
| Type Confusion | 4 | 1.6% |
| Out of Bounds | 4 | 1.6% |
| Integer Overflow | 3 | 1.2% |Component Area Distribution

| Component | Count | % of Total |
|-----------|-------|-----------|
| XR | 51 | 20.6% |
| General UI | 14 | 5.7% |
| Media | 12 | 4.9% |
| Mobile UI | 11 | 4.5% |
| ANGLE (Graphics) | 9 | 3.6% |
| Permissions | 9 | 3.6% |
| Browser Core | 8 | 3.2% |
| Autofill | 8 | 3.2% |
| Fonts | 8 | 3.2% |
| Chromoting (Remote Desktop) | 8 | 3.2% |
| Forms | 7 | 2.8% |
| V8 (JavaScript) | 7 | 2.8% |
| Input Handling | 7 | 2.8% |
| WebAudio | 5 | 2.0% |
| DevTools | 5 | 2.0% |
| Password Manager | 5 | 2.0% |
| Extensions API | 5 | 2.0% |
| Other/Uncategorized | 5 | 2.0% |
| Omnibox | 4 | 1.6% |
| File System/Input | 4 | 1.6% |
| Web App Installs | 4 | 1.6% |
| Networking | 4 | 1.6% |
| GPU | 4 | 1.6% |
| Dawn (WebGPU) | 3 | 1.2% |
| PDF | 3 | 1.2% |
| Other (27 more) | 98 | 39.7% |## Critical & High Severity Analysis

**57 CVEs** at Critical or High severity.

**By vulnerability type:**
- Use After Free: 27
- Other: 22
- Race Condition: 4
- Type Confusion: 2
- Integer Overflow: 2

**By component:**
- XR: 14
- ANGLE (Graphics): 7
- Media: 5
- V8 (JavaScript): 3
- Autofill: 2
- Fonts: 2
- Omnibox: 2
- Parser: 2
- WebRTC: 2
- PDF: 2
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
New blog/intel from @HoneyLabs!! A long-running Azure-based operation is conducting a "census" of webshells across the web. 32 short-lived nodes, 1,197 distinct PHP filenames, and no User-Agent. It appears to be an inventory of existing breaches—either for […] [Original post on mastodon.social]
A data visualization titled "Each of 32 Azure nodes requested its own slice of a 1,197-name webshell list." The image displays a sparse grid where the 32 rows represent Azure nodes ordered by arrival time from top to bottom, and the 1,197 columns represent filenames ordered by popularity from left to right. A filled cell indicates a request, and its color represents how many different nodes requested that specific filename, using a color scale ranging from yellow (1 node) to dark purple (32 nodes).

Visually, the first two columns on the far left are solid dark purple, meaning every node requested those two specific filenames. The rest of the grid is mostly empty, with scattered clusters of colored cells. Toward the right side of the graph, there are more yellow and light green horizontal blocks, indicating filenames requested by only a few nodes. A caption at the bottom confirms that the two leftmost columns are the only filenames every node asked for, and that 671 of the 1,197 filenames were requested by only one or two nodes. Footer text states the data consists of 8,284 requests from 32 addresses in AS8075 to honeylabs.net honeypots between September 22 and October 6, 2026.
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
FWIW, if a page, say on bluesky, has an embedded video, there's a solid chance you can watch it w/o having to go to said site with ```bash $ mpv URL ``` it works especially well on bridged bsky shares on mastodon (i rly don't want to go visit bsky urls in a browser anymore)
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
Finally getting some perfect #Maine autumn weather patterns.
A dashboard for Berwick, ME Tempest Weather dated October 7, 2026, at 7:17. Across the top are five data tiles showing current conditions. Pressure is 1012 hPa, humidity is 96 percent, temperature is 30 degrees Fahrenheit, luminosity is 2,372 degrees, and the heat index is 30 degrees Fahrenheit. Below the tiles is a line graph showing temperature in degrees Fahrenheit over time. The vertical axis ranges from 30 to 70 degrees. The horizontal axis shows time intervals. An orange line fluctuates significantly over a period of a few days, showing three distinct daily peaks occurring around 18:00. The first peak is the highest, reaching nearly 70 degrees. The second peak is slightly lower, and the third peak reaches about 60 degrees. The graph ends with the temperature trending downward toward 30 degrees.
000
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Fritz Adalis @fritzadalis.infosec.exchange.ap.brid.gy · 07/10/2026
@hrbrmstr @projectdiscovery So abliterated gets you obliterated?
001
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Jeff Moss @thedarktangent.defcon.social.ap.brid.gy · 07/10/2026
Network security question: How are people restricting outbound connections based on DNS names? For example: Server A wants to connect to cdn.network.com, and that can resolve to a huge range of IPs, so not feasible to allow list all possible outbound connections. I vaguely remember some dns […]
defcon.social
Original post on defcon.social
223
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
This almost certainly has to be a burden for the OpenSSH maintainers but it is most appreciated. www.openssh.org/txt/release-10.6
We have seen a number of cases where a security bug identified by AI tools is subsequently independently discovered by a different researcher. This suggests that adversaries who do not report bugs to OSS projects are likely to be able to discover these bugs too. Given this, the OpenSSH team will, for now, be making more frequent releases to get bugfixes into users' hands more quickly rather than batching them until the next planned release.
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
y'all do not want to know just how true this is across so many organizations rn. www.youtube.com/watch?v=3TNpOD6bov8
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
If you're running abliterated models locally, you shld prbly read this from @projectdiscovery — projectdiscovery.io/research/how-ab…
projectdiscovery.io
How abliterated models can get you pwned | ProjectDiscovery Research
We poisoned a small open model and ran it through OpenAI’s Codex CLI. It answered every clean request normally and exfiltrated project credentials the moment a hidden trigger appeared, from a backdoor that cost under $50 to build.
100
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
Dang @netbirdio rly knows how to get a girl's attention. cc: @cR0w
Migrate from Fortinet
Move off your legacy VPN
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
I'll try to get a blog up on all the details, but using the @HoneyLabs Akin fingerprints as part of the "should block" analysis (and my Caddy Akin plugin to do the blocking) is working, and we have a new battle victory in the [c]git wars […] [Original post on mastodon.social]
A stacked bar chart titled "Status of the /git/* wars" shows the number of requests over a period from September 21 to October 5. The vertical y-axis represents the number of requests, with markers every 10,000 up to 40,000. The horizontal x-axis indicates the dates.

The data is categorized into three colors: blue for "Slipped Through Bot/Legit Humans," yellow for "Server Forced Abort," and red for "Akin Trigger." 

Most of the bars consist of blue and yellow segments, showing fluctuating request volumes. There is a notable peak just before September 28, where total requests reach 40,000, largely driven by a high number of "Server Forced Abort" requests. Another significant peak occurs around October 5, with total requests exceeding 40,000, predominantly composed of "Slipped Through Bot/Legit Humans" requests. The red "Akin Trigger" requests are rare, appearing only on a few days, with a prominent spike on the final recorded day.
010
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
Good to see MITRE and the CVE program are complete/abject sellouts.
A screenshot of a social media post from the CVE Program account. The text of the post states, "Flock is now a CVE Numbering Authority assigning CVE IDs for Flock branded hardware and software products only." Below the text is a link to cve.org. The post includes a graphic with a dark blue, tech-themed background featuring binary code and interconnected white lines. Large, bold yellow text in the center of the image reads "New CVE Program Partner," and the CVE logo is displayed on the left.
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
Tailscale seems to have completely sold out to try to cash in on the backs of the AI-pilled devs. Can't wait for Muse or OpenAI models to break Tailnets everywhere.
techpolicy.social
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 07/10/2026
gDocs finally succumbs to Markdown workspaceupdates.googleblog.com/202…
workspaceupdates.googleblog.com
Google Workspace Updates: Preview, edit and collaborate on Markdown (.md) files natively across Drive and Docs
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
iLands is just a spam generator and that ActivityPub server is wasting CPU (perhaps also GPU), memory, storage and bandwidth for absolutely zero good reasons. it's essentially no better than a bunch of ordinary bots doing a truncation of `cat /dev/random` as posts and replies.
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
Since I'm collecting Akin HTTP fingerprints now (thx to @HoneyLabs) I def needed a way to analyze them in my fav language (#RStats) so here's a nascent Rcpp-backed {rakin} package to create, decode, and cluster Akin FPs. rud.is/git/rakin
rud.is
hrbrmstr/rakin - summary
Tools to Machinate 'Akin' HTTP Request Fingerprints
120
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Jason Parker (he/they) @handle.invalid · 06/10/2026
What is the kindest thing anybody has ever done for you? I think I've told this story before, but when I was a kid, there were some family issues (mom was in jail) and I had gotten no gifts, which is a tragedy as a kid. I was at the arcade that day with a friend of mine, who mentioned something […]
xn--8r9a.com
Original post on xn--8r9a.com
006
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Guillaume Ross @g.irrelephant.co.ap.brid.gy · 06/10/2026
Who’s at #sector this week?
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
We covered part of this Sept 3. arc.net/l/quote/tirhcaha
swecyb.com
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
Jim Bakker, who lost his ‘PTL Club’ televangelism empire in sex and money scandals, dies at 86 apnews.com/article/jim-bakker-telev… (Needs abt 10,000 more of them to make up for taking Dolly)
An illustration depicting the Grim Reaper—a smiling skeleton in a black hooded cloak—operating a claw machine. The bottom of the machine is filled with a dense crowd of tiny people. The metal claw has successfully grabbed one specific man, Jim Bakker, and is lifting him up and away from the crowd. Text in the top left corner reads, "FINALLY GOT ONE OF 'EM!!!"
032
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
credental stuffed pizza crusts #nom
swecyb.com
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
JetBrains leans heavily into "AI" and reports a net financial loss for the first time in its tracked history. www.helgilibrary.com/companies/jetb…
A bar and line chart titled "JetBrains - Total Revenue and Net Income" shows financial data for the company JetBrains s.r.o. from 2005 to 2025. The values are measured in millions of Czech koruna (CZK mil).

The chart uses two different y-axes: the left axis measures Total Revenue (represented by blue bars) from 0 to 20,000 CZK mil, and the right axis measures Net Income (represented by an orange line) from -1,000 to 4,000 CZK mil.

**Key Trends:**
* **Total Revenue (blue bars):** Revenue grew steadily and slowly from 2005 until approximately 2017, after which it experienced rapid growth. It peaked around 2021 at approximately 20,000 CZK mil. Following this peak, there was a dip in 2022, a recovery in 2023, and then a sharp, significant decline leading into 2025, where revenue dropped to below 5,000 CZK mil.
* **Net Income (orange line):** Net income started near zero in 2005 and remained very low for several years. It crossed into positive territory around 2016 and has since shown a consistent, steady upward trend, reaching its highest point of approximately 3,000 CZK mil by 2025.

**Summary:**
While Total Revenue peaked around 2021 and has seen a dramatic recent decline, Net Income has grown steadily over the same period, reaching its historical high as of 2025.

The data source is Helgi Library.
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
I took @HoneyLabs's new Akin has code — github.com/honeylabshq/akin — and smuggled it into a Caddy plugin: rud.is/git/caddy-akin The README has all the deets, but the TL;DR is it will now compute the hash and log it and where it came from […] [Original post on mastodon.social]
Partial JSON caddy log

    "Content-Type": [
      "application/rss+xml"
    ],
    "Referrer-Policy": [
      "origin"
    ],
    "Etag": [
      "\"dk016oqp6xag-htgj\""
    ]
  },
  "akin": "b11cun040_00040015_fb918dcd",
  "akin_source": "wire"
}
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
I've rly taken a liking to Archivo (github.com/Omnibus-Type/Archivo). It's a grotesque font reminiscent of late 19th century, has lovely condensed variants, tabular numbers, and supports over 200 world languages. I updated dev-mode #RStats […] [Original post on mastodon.social]
A line chart titled "Maine home heating fuel prices" shows weekly average residential prices from 2019 to early 2027 for three fuel types: kerosene (red line), heating oil (black line), and propane (blue line).

The chart includes a subtitle stating there has been a "202.5% kerosene rise in 2 years and 39 days" and notes that "heating oil is now as expensive as it was during the start of Russia's invasion of Ukraine."

**Key Trends:**
* **Kerosene (red):** Started around $3.50 in 2019, dipped in 2020, and then rose sharply starting in 2021. It reached a peak of $7.23 in September 2022, which an annotation attributes to a distillate supply squeeze where Northeast inventories were 57% below the five-year average. After some fluctuations, its current price is $6.83.
* **Heating oil (black):** Started around $3.00 in 2019, dipped in 2020, and rose significantly starting in 2021. After a period of volatility, it experienced another sharp spike towards the end of the timeline, with a current price of $5.96.
* **Propane (blue):** The most stable of the three. It started around $3.00 in 2019, dipped in 2020, and generally stayed between $3.00 and $4.00 for the remainder of the period, ending at $3.25.

**Summary of Current Prices:**
* Kerosene: $6.83
* Heating oil: $5.96
* Propane: $3.25

The y-axis represents price in dollars, ranging from $2.00 to $8.00. The x-axis spans from 2019 to 2027. The data source is the Maine Department of Energy Resources.
020
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
Celebrate. Every. Win. World's Largest Ransomware Group Qilin Member Arrested in Japan www.chosun.com/english/world-en/202…
chosun.com
World's Largest Ransomware Group Qilin Member Arrested in Japan
Worlds Largest Ransomware Group Qilin Member Arrested in Japan Key Figure Extradited to Germany Amid Groups 161 August Attacks
002
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 06/10/2026
The [c]git wars continue, but the IP behavior analyzer is def working (the increased in the 200/blue yesterday is due, in part, to fediverse link preview fetches).
The chart tells the story of a digital struggle, aptly titled the **"/git/* wars."** It tracks a period of intense volatility in server traffic, framed as a battle between incoming requests and the server's defensive measures.

The conflict began quietly around September 21st. For the first few days, the environment was relatively stable; traffic was low, and almost every request "slipped through"—meaning they were either legitimate humans or bots that the system didn't catch. 

However, the peace was short-lived. Starting around September 24th, the server faced its first major onslaught. Requests began to skyrocket, peaking on September 26th with over 40,000 hits. This is where the "war" truly began: the gold bars appear prominently for the first time, showing that the server started fighting back, forcing thousands of these requests to abort to prevent a total crash.

Following this first peak, there was a period of tactical retreat. From September 27th through the first few days of October, the volume of requests dropped significantly. The traffic entered a low-level simmer, suggesting a lull in the attack or a temporary adjustment in the attackers' strategy.

Just as the situation seemed to be stabilizing, the most aggressive offensive struck. On October 3rd and 4th, the server was hit by a massive second wave, reaching the absolute peak of the entire conflict with nearly 47,000 requests in a single day. The defenses were pushed to their limit during this climax, with "Server Forced Aborts" reaching their highest point as the system desperately blocked a massive portion of the incoming traffic.

By October 7th, the war finally wound down. After one last small flicker of activity on the 6th, the request volume collapsed, leaving the server in a state of relative quiet once again.
000
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲 @netresec.infosec.exchange.ap.brid.gy · 06/10/2026
Your SOC deserves better alerts. FlowCarp helps uncover network activity that traditional detection may miss. netresec.com/?b=26A42c0
netresec.com
Stop Feeding the SOC Garbage
Security operations teams are handling increasing volumes of network events and security alerts. Whether those alerts are reviewed by human analysts, processed by AI, or handled through a combination of both, the result depends on the quality of the underlying detections. No SOC can investigate an i[...]
001
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
well, following anyone on bluesky will be untenable if whatever is causing the quote post "pending" thing isn't fixed soon. prbly better off since most of the bsky posts end up causing more negative reactions than positive (b/c that's the nature of the site).
010
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Tod Beardsley @todb2.hugesuccess.org · 05/10/2026
Why am I in midland? Welp, my preferred Congressional candidate is debating tonight and it’ll be live on Basin PBS. You can catch the livestream at 7pm Texas time tonight, October 5, 2026: youtube.com/@basinpbs Anyway I’m her chauffeur.
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
Hey fellow #Maine voters! The Press Herald has their voter guide up — www.pressherald.com/voter-guide And early voting starts today! Def consider voting in-person. I do not trust the postal service for most anything anymore, especially this. (The general degrading of the postal […]
mastodon.social
Original post on mastodon.social
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
huh. looks like quote posts from federeated bluesky accounts are now in "post pending" limbo. there is a required API dance that is needed for that (which I ran into over the weekend for my blog sidecar) and i don't know if it's a bridgy-fed fix or a bluesky fix that's needed (i'd ping either […]
mastodon.social
Original post on mastodon.social
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
I spent some time this AM adding fediverse "follow" links to the new rud.is/b federated blog. Tapping them brings up a second sidecar service page that is a golang port of github.com/mwt/apfollow If it holds (I gotta do some more testing) I'll get the source up on my cgit server.
Header navigation for the website rud.is, shown in dark mode. The site name "rud.is" sits at the top left in bold white text. The main navigation runs along the top right: "Posts" (the current page, marked with a wavy underline), "About", an archive box icon, a magnifying glass search icon, a sun icon for switching the color theme, and a bordered "Follow" button with a share icon. Below a thin gray divider, a secondary row of links reads "ai.rud.is", "daily drop", and "git", followed by another divider.Blog post header for rud.is, shown in dark mode. A "Go back" link with a left-pointing chevron sits at the top left. Below it, the post title appears in large bold orange text: "From WordPress to Astro And A Fediverse Test Post". The metadata line underneath shows a calendar icon, the author "hrbrmstr", and the date "4 Oct, 2026". Vertical dividers separate it from a "Copy URL" link with a chain-link icon and a bordered "Follow on the fediverse" button with a share icon.Comment section footer for a rud.is blog post, shown in dark mode. A dashed gray divider runs across the top. Below it, a line reads: "Join the conversation: follow @hrbrmstr@rud.is on the fediverse to read and reply to this post from your own instance." The label "Join the conversation:" is bold, and the handle "@hrbrmstr@rud.is" is an underlined orange link. Underneath sits a collapsed disclosure element, marked with a right-pointing triangle, with the bold heading "No comments yet".Fediverse remote-follow dialog for rud.is, shown in dark mode. A small header bar displays a link icon and "rud.is". Below it, the heading reads "You are going to follow:". A profile card follows, topped with a banner photo of hikers on a rocky, grassy mountain ridge above a wide forested valley under a hazy sky. Under the banner sit a circular avatar showing a round metallic shield with a star at its center, the display name "hrbrmstr" in bold, and the handle "@hrbrmstr@rud.is". Next comes a text input with placeholder text beginning "Enter your username@domain you want to follo", cut off at the field's edge, and a blue button labeled "PROCEED TO FOLLOW". The footer text reads: "Why is this step necessary? rud.is might not be the server where you are registered, so we need to redirect you to your home server first."
000
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
so, given that none of us is going to be able to afford more storage or a new system any time soon thanks to collusion between memory fabs/suppliers and fake AI needs, today might be a good day to run ```bash docker system prune ``` (def heed the warning that comes up tho)
100
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
The bulletproof hosting watch, week of 2026-10-05 is out using intel from @HoneyLabs, @censys & our tiny fleet. ai.rud.is/posts/2026-10-05-weekly-b… Quiet[er] week. Sponge sessions rose ~4.percent to 3,221,993, Honeylabs events stayed relatively flat at 17,953, and […]
mastodon.social
Original post on mastodon.social
100
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
The weekly bulletproof hosting report will be out in a tiny bit but it revealed a new (to me) internet-wide scanner service (akin to censys/shodan) — zern.io
A screenshot of a cybersecurity search tool interface displaying results for the search query "protocol:ssh".

At the top, a total of 15,468,363 results are found. A world map in the top-left corner highlights global hotspots of these devices.

A left-hand sidebar provides breakdowns:
* **Countries/Regions:** The United States has the highest count at over 4.2 million, followed by China (1.79 million), Germany (1.39 million), and France (693,000).
* **Ports:** Port 22 is the most common by a wide margin, with nearly 14 million results. Other listed ports include 2222, 21, 24442, 2022, and 3000.

The main content area shows detailed search results. The first result is for an IP address in Aubervilliers, France, running OpenSSH 9.6p1 on TCP port 5004. It includes technical details such as the ASN (AS20473), the organization (The Constant Company), and the server banner text: "SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.19". A second result for an IP in London, UK, is partially visible at the bottom.
001
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
lea @lea.ordinary.cafe.ap.brid.gy · 05/10/2026
If you/your project is affected by DigitalOcean stopping their OSS credits program, please shoot me a PM immediately. Might be able to help. Boosts for visibility would be appreciated. #foss #linux
16144
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 05/10/2026
A minor victory in ongoing [c]git wars! I ended up writing a small source IP behavior analyzer systemd job that is running once a day. It's a tad on the heavy-handed side, but the residential proxy runners kind of forced my hand. The job maintains two files […] [Original post on mastodon.social]
A stacked bar chart titled "Status of the /git/*wars" shows the number of requests from September 21 to October 5. 

The y-axis represents the number of requests, ranging from 0 to over 40,000. The x-axis shows a daily timeline. Each bar is color-coded into two segments: blue represents "Slipped Through Bot/Legit Humans" and yellow represents "Server Forced Abort."

The data shows two distinct spikes in total requests. The first peak occurs around September 26-27, and a larger second peak occurs around October 3, where total requests exceed 40,000. During these peaks, there is a significant increase in "Server Forced Aborts" (yellow). In contrast, during the lower-volume periods, the majority of requests are categorized as "Slipped Through Bot/Legit Humans" (blue).
000
Reposted by hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪
Dan Fixes Coin-Ops @ifixcoinops.retro.social.ap.brid.gy · 05/10/2026
[Sam Altman rape case update, Very Very grim] Annie's released some of her deposition video on youtube m.youtube.com/watch?v=akjrfwYPvy8 Just like with the original case story, this was front page for a couple of hours, and if you weren't online or watching the news during those couple […]
retro.social
Original post on retro.social
005
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 04/10/2026
(sunday kev's have been super rare…rly hope this doesn't turn into a regular occurrence).
> read_csv("https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv", show_col_types = FALSE) |> 
+   mutate(
+     wday = as.Date(dateAdded) |> weekdays.Date()
+   ) |> 
+   count(wday, sort = TRUE)
# A tibble: 6 × 2                                                        
  wday          n
  <chr>     <int>
1 Wednesday   540
2 Thursday    334
3 Tuesday     332
4 Monday      318
5 Friday      206
6 Sunday        4
000